Product
high
advisory
Detection of Multi-Cloud CLI Token and Credential Harvesting
2 TTPsThreat actors harvest cloud and container platform authentication tokens by abusing legitimate CLI utilities to output secrets to standard streams, which can be detected via anomalous multi-provider access patterns.
Google Cloud SDK +6
credential-access
cloud-security
supply-chain
2t
updated
high
advisory
Multiple Vulnerabilities in Microsoft Azure, Entra, and Azure CLI
3 TTPsMultiple vulnerabilities across Microsoft Azure, Entra, and Azure CLI allow for identity impersonation, unauthorized data access, privilege escalation to SYSTEM level, and arbitrary code execution.
Azure +2
entra
cloud-security
vulnerability
identity-security
3t
medium
advisory
Detect Windows Entra User Management Via Azure CLI
2 rules 3 TTPsThis analytic detects the usage of the Azure CLI to interact with user accounts, such as creating or deleting a user, potentially indicating malicious activity aimed at maintaining persistence and evading detection within an Entra ID environment.
Azure CLI +3
azure
entra-id
user-management
persistence
windows
2r
3t